RULE(RULE ID:330099)

Rule General Information
Release Date: 2020-05-14
Rule Name: HAProxy cookie Denial of Service Vulnerability (CVE-2019-14241)
Severity:
CVE ID:
Rule Protection Details
Description: HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Linux
Reference: SecurityFocusBID:109352
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00060.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00062.html
https://github.com/haproxy/haproxy/issues/181
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/haproxy/haproxy/issues/181